Papers
Topics
Authors
Recent
Search
2000 character limit reached

A 2n/22^{n/2}-Time Algorithm for n\sqrt{n}-SVP and n\sqrt{n}-Hermite SVP, and an Improved Time-Approximation Tradeoff for (H)SVP

Published 19 Jul 2020 in cs.DS | (2007.09556v1)

Abstract: We show a 2<sup>n/2+o(n)2<sup>{n/2+o(n)}-time algorithm that finds a (non-zero) vector in a lattice L⊂R<sup>n\mathcal{L} \subset \mathbb{R}<sup>n with norm at most O~(n)⋅min⁡λ1(L),det⁡(L)<sup>1/n\tilde{O}(\sqrt{n})\cdot \min{\lambda_1(\mathcal{L}), \det(\mathcal{L})<sup>{1/n}}, where λ1(L)\lambda_1(\mathcal{L}) is the length of a shortest non-zero lattice vector and det⁡(L)\det(\mathcal{L}) is the lattice determinant. Minkowski showed that λ1(L)≤ndet⁡(L)<sup>1/n\lambda_1(\mathcal{L}) \leq \sqrt{n} \det(\mathcal{L})<sup>{1/n} and that there exist lattices with λ1(L)≥Ω(n)⋅det⁡(L)<sup>1/n\lambda_1(\mathcal{L}) \geq \Omega(\sqrt{n}) \cdot \det(\mathcal{L})<sup>{1/n}, so that our algorithm finds vectors that are as short as possible relative to the determinant (up to a polylogarithmic factor). The main technical contribution behind this result is new analysis of (a simpler variant of) an algorithm from arXiv:1412.7994, which was only previously known to solve less useful problems. To achieve this, we rely crucially on the ``reverse Minkowski theorem'' (conjectured by Dadush arXiv:1606.06913 and proven by arXiv:1611.05979), which can be thought of as a partial converse to the fact that λ1(L)≤ndet⁡(L)<sup>1/n\lambda_1(\mathcal{L}) \leq \sqrt{n} \det(\mathcal{L})<sup>{1/n}. Previously, the fastest known algorithm for finding such a vector was the 2<sup>.802n</sup>+o(n)2<sup>{.802n</sup> + o(n)}-time algorithm due to [Liu, Wang, Xu, and Zheng, 2011], which actually found a non-zero lattice vector with length O(1)⋅λ1(L)O(1) \cdot \lambda_1(\mathcal{L}). Though we do not show how to find lattice vectors with this length in time 2<sup>n/2+o(n)2<sup>{n/2+o(n)}, we do show that our algorithm suffices for the most important application of such algorithms: basis reduction. In particular, we show a modified version of Gama and Nguyen's slide-reduction algorithm [Gama and Nguyen, STOC 2008], which can be combined with the algorithm above to improve the time-length tradeoff for shortest-vector algorithms in nearly all regimes, including the regimes relevant to cryptography.

Citations (12)

Summary

No one has generated a summary of this paper yet.

Paper to Video (Beta)

No one has generated a video about this paper yet.

Whiteboard

No one has generated a whiteboard explanation for this paper yet.

Open Problems

We haven't generated a list of open problems mentioned in this paper yet.

Continue Learning

We haven't generated follow-up questions for this paper yet.